設定的網路原則伺服器計量Configure Network Policy Server Accounting

有三種類型的網路原則伺服器 (NPS) 登入:There are three types of logging for Network Policy Server (NPS):

  • 事件登入Event logging. 主要用於稽核和連接嘗試進行疑難排解。Used primarily for auditing and troubleshooting connection attempts. 您可以設定 NPS 事件取得 NPS 伺服器屬性 NPS 主機登入。You can configure NPS event logging by obtaining the NPS server properties in the NPS console.

  • 登入本機的檔案的驗證使用者以及計量要求Logging user authentication and accounting requests to a local file. 主要用來連接分析及計費用途。Used primarily for connection analysis and billing purposes. 也很有用,做為安全性調查工具因為您提供攻擊後追蹤惡意使用者的活動的方法。Also useful as a security investigation tool because it provides you with a method of tracking the activity of a malicious user after an attack. 您可以設定使用計量組態精靈本機檔案登入。You can configure local file logging using the Accounting Configuration wizard.

  • 登入的 Microsoft SQL Server 相容 XML 資料庫驗證使用者以及計量要求Logging user authentication and accounting requests to a Microsoft SQL Server XML-compliant database. 用來讓多部伺服器執行 NPS 有一個資料來源。Used to allow multiple servers running NPS to have one data source. 也提供使用的關係資料庫的優點。Also provides the advantages of using a relational database. 您可以使用 [計量組態精靈設定 SQL Server 登入。You can configure SQL Server logging by using the Accounting Configuration wizard.

使用計量組態精靈Use the Accounting Configuration wizard

藉由使用計量設定精靈中,您可以設定下列四個計量設定:By using the Accounting Configuration wizard, you can configure the following four accounting settings:

  • 僅限 SQL 登入SQL logging only. 使用此設定,您可以設定可連接至並計量資料傳送至 SQL server NPS SQL Server 的資料的連結。By using this setting, you can configure a data link to a SQL Server that allows NPS to connect to and send accounting data to the SQL server. 此外,精靈可以資料庫設定 SQL Server 以確保資料庫相容具有 NPS SQL server 登入。In addition, the wizard can configure the database on the SQL Server to ensure that the database is compatible with NPS SQL server logging.
  • 僅限文字登入Text logging only. 使用此設定,您可以設定 NPS 登入計量資料文字檔案。By using this setting, you can configure NPS to log accounting data to a text file.
  • 平行登入Parallel logging. 使用此設定,您可以設定的資料 ] 連結 SQL Server 和資料庫。By using this setting, you can configure the SQL Server data link and database. 您也可以設定文字檔案登入,以便 NPS 登同時文字檔案和 SQL Server 資料庫。You can also configure text file logging so that NPS logs simultaneously to the text file and the SQL Server database.
  • 備份與 SQL 登入SQL logging with backup. 使用此設定,您可以設定的資料 ] 連結 SQL Server 和資料庫。By using this setting, you can configure the SQL Server data link and database. 此外,您可以設定 NPS 使用 SQL Server 登入失敗時,文字檔案登入。In addition, you can configure text file logging that NPS uses if SQL Server logging fails.

除了這些設定,請同時 SQL Server 登入和文字登入可讓您指定 NPS 是否要繼續處理連接要求如果登入失敗。In addition to these settings, both SQL Server logging and text logging allow you to specify whether NPS continues to process connection requests if logging fails. 您也可以在此指定登入失敗動作] 區段在本機檔案登入屬性,SQL server 登入屬性,以及當您正在執行計量設定精靈。You can specify this in the Logging failure action section in local file logging properties, in SQL server logging properties, and while you are running the Accounting Configuration Wizard.

若要執行計量設定精靈To run the Accounting Configuration Wizard

若要執行計量設定精靈中,請完成下列步驟:To run the Accounting Configuration Wizard, complete the following steps:

  1. NPS 主機或 NPS Microsoft Management Console (MMC) 嵌入式管理單元開放。Open the NPS console or the NPS Microsoft Management Console (MMC) snap-in.
  2. 主控台中,按一下 [計量In the console tree, click Accounting.
  3. 在詳細資料窗格中,在計量,按一下 [設定計量In the details pane, in Accounting, click Configure Accounting.

設定 NPS 登入檔案屬性Configure NPS Log File Properties

您可以設定的網路原則伺服器 (NPS) 到執行遠端驗證 Dial 使用者服務 (RADIUS) 計量使用者驗證要求,存取接受訊息、存取-退回訊息、計量要求和回應,以及狀態定期的更新。You can configure Network Policy Server (NPS) to perform Remote Authentication Dial-In User Service (RADIUS) accounting for user authentication requests, Access-Accept messages, Access-Reject messages, accounting requests and responses, and periodic status updates. 若要設定您要儲存計量資料登入檔案,您可以使用此程序。You can use this procedure to configure the log files in which you want to store the accounting data.

如需有關解譯登入檔案,請查看上尚未取得共識檔案 NPS 資料庫格式登入For more information about interpreting log files, see Interpret NPS Database Format Log Files.

若要防止填滿硬碟登入檔案,建議您將它們保存在不同的系統磁碟分割的磁碟分割。To prevent the log files from filling the hard drive, it is strongly recommended that you keep them on a partition that is separate from the system partition. 以下提供設定計量 NPS 的相關資訊:The following provides more information about configuring accounting for NPS:

  • 若要傳送檔案的登入資料收集其他處理程序,您可以設定 NPS 寫入命名管道。To send the log file data for collection by another process, you can configure NPS to write to a named pipe. 若要使用管道命名,設定 \.\pipe 或 \ComputerName\pipe 登入檔案的資料夾。To use named pipes, set the log file folder to \.\pipe or \ComputerName\pipe. 命名的管道伺服器程式建立命名的管道稱為 \.\pipe\iaslog.log 接受資料。The named pipe server program creates a named pipe called \.\pipe\iaslog.log to accept the data. 本機檔案屬性對話方塊中,在 [建立新的登入檔案,不會(無限制的檔案的大小)選取當您使用名的管道。In the Local file properties dialog box, in Create a new log file, select Never (unlimited file size) when you use named pipes.

  • 登入檔案 directory 可以使用系統環境變數(而不是使用者變數),例如 %系統磁碟機、systemroot %及 %windir%建立。The log file directory can be created by using system environment variables (instead of user variables), such as %systemdrive%, %systemroot%, and %windir%. 例如,下列路徑,使用環境變數 %windir%,找出登入檔案,系統 directory 在子資料夾 \System32\Logs (也就是 %windir%\system32\logs)。For example, the following path, using the environment variable %windir%, locates the log file at the system directory in the subfolder \System32\Logs (that is, %windir%\System32\Logs).

  • 切換登入的檔案格式不會建立新的登入。Switching log file formats does not cause a new log to be created. 如果變更登入的檔案格式,變更的時間位於使用中的檔案將會包含兩種格式多種(記錄登入的開頭有先前格式,且記錄結尾的登入新的格式)。If you change log file formats, the file that is active at the time of the change will contain a mixture of the two formats (records at the start of the log will have the previous format, and records at the end of the log will have the new format).

  • 如果 RADIUS 計量失敗因為完整硬碟或其他原因,NPS 停止處理連接要求,導致使用者存取網路資源。If RADIUS accounting fails due to a full hard disk drive or other causes, NPS stops processing connection requests, preventing users from accessing network resources.

  • NPS 提供的能力來登入 Microsoft® SQL Server™ 資料庫而不是,或登入至本機的檔案。NPS provides the ability to log to a Microsoft® SQL Server™ database in addition to, or instead of, logging to a local file.

資格在網域系統管理員群組是的最低需求才能執行此程序。Membership in the Domain Admins group is the minimum required to perform this procedure.

若要設定 NPS 登入檔案屬性To configure NPS log file properties

  1. NPS 主機或 NPS Microsoft Management Console (MMC) 嵌入式管理單元開放。Open the NPS console or the NPS Microsoft Management Console (MMC) snap-in.
  2. 主控台中,按一下 [計量In the console tree, click Accounting.
  3. 在詳細資料窗格中,在登入檔案屬性,按一下 [變更登入檔案屬性In the details pane, in Log File Properties, click Change Log File Properties. 登入檔案屬性對話方塊。The Log File Properties dialog box opens.
  4. 登入檔案屬性,在設定索引標籤登入下列資訊,確認您選擇登入資訊不足,無法達到計量目標。In Log File Properties, on the Settings tab, in Log the following information, ensure that you choose to log enough information to achieve your accounting goals. 例如,若您登完成工作階段相關,請選取所有核取方塊。For example, if your logs need to accomplish session correlation, select all check boxes.
  5. 登入失敗動作如果登入失敗時,會捨棄連接要求如果您想要停止處理要求存取訊息時登入的檔案完全或無法使用某些原因 NPS。In Logging failure action, select If logging fails, discard connection requests if you want NPS to stop processing Access-Request messages when log files are full or unavailable for some reason. 如果您想繼續處理連接要求如果登入失敗 NPS,不會選取此核取方塊。If you want NPS to continue processing connection requests if logging fails, do not select this check box.
  6. 登入檔案屬性對話方塊中,按登入檔案索引標籤。In the Log File Properties dialog box, click the Log File tab.
  7. 設定檔登入索引標籤的Directory,輸入您想要儲存 NPS 登入檔案的位置。On the Log File tab, in Directory, type the location where you want to store NPS log files. 預設位置為 systemroot\System32\LogFiles 資料夾。The default location is the systemroot\System32\LogFiles folder. >[!NOTE] >如果您不提供完整路徑陳述在登入檔案 Directory,使用預設的路徑。If you do not supply a full path statement in Log File Directory, the default path is used. 例如,如果您輸入NPSLogFile登入檔案 Directory,位於 %systemroot%\system32\npslogfile 檔案。For example, if you type NPSLogFile in Log File Directory, the file is located at %systemroot%\System32\NPSLogFile.
  8. 格式,按一下 [ DTS 相容In Format, click DTS Compliant. 如果您想要的話,您可以改為選取的舊版檔案格式,例如ODBC (Legacy)IAS (Legacy)If you prefer, you can instead select a legacy file format, such as ODBC (Legacy) or IAS (Legacy). >[!NOTE] >ODBCIAS的舊版檔案類型包含子集 NPS 將傳送至其 edition 的資訊。ODBC and IAS legacy file types contain a subset of the information that NPS sends to its SQL Server database. 相容 DTS是 NPS 使用資料匯入到其 edition XML 格式相同的檔案類型 XML 格式。The DTS Compliant file type’s XML format is identical to the XML format that NPS uses to import data into its SQL Server database. 因此,相容 DTS的檔案格式 NPS 提供更有效率且完整的資料傳送到標準 SQL Server 資料庫。Therefore, the DTS Compliant file format provides a more efficient and complete transfer of data into the standard SQL Server database for NPS.
  9. 建立新的檔案登入,若要設定新的登入檔案,指定的時間間隔,[開始] 中,按一下您想要使用的時間間隔 NPS:In Create a new log file, to configure NPS to start new log files at specified intervals, click the interval that you want to use:
    • 對於大量交易音量與登入活動中,按一下每天For heavy transaction volume and logging activity, click Daily.
    • 較少交易磁碟區及登入的活動,按每月For lesser transaction volumes and logging activity, click Weekly or Monthly.
    • 若要儲存的所有交易登入一個檔案,請按一下永不 (unlimited file size)To store all transactions in one log file, click Never (unlimited file size).
    • 若要限制登入的每個檔案的大小,請按一下 [登入檔大小的到達時,然後輸入較檔案的大小,建立新的登入之後。To limit the size of each log file, click When log file reaches this size, and then type a file size, after which a new log is created. 預設的大小是 10 mb。The default size is 10 megabytes (MB).
  10. 如果您想 NPS delete 舊的登入檔案,以建立新的登入檔案的磁碟空間容量硬碟時,請確定磁碟時完整 delete 較舊的登入檔案選取。If you want NPS to delete old log files to create disk space for new log files when the hard disk is near capacity, ensure that When disk is full delete older log files is selected. 不此選項,不過,如果的值建立新的檔案登入永不 (unlimited file size)This option is not available, however, if the value of Create a new log file is Never (unlimited file size). 同時,如果登入舊檔案目前登入檔案,它並不刪除。Also, if the oldest log file is the current log file, it is not deleted.

NPS SQL Server 登入的設定Configure NPS SQL Server Logging

您可以使用此程序來登入 RADIUS 計量資料到 Microsoft SQL server 本機或遠端資料庫。You can use this procedure to log RADIUS accounting data to a local or remote database running Microsoft SQL Server.

注意

NPS 格式計量資料的 XML 文件,並將傳送至為report_event您在 NPS 指定 SQL Server 資料庫中儲存程序。NPS formats accounting data as an XML document that it sends to the report_event stored procedure in the SQL Server database that you designate in NPS. 登入,才能正常 SQL Server 中,您必須有儲存程序名為report_event可以收到和剖析 NPS 的 XML 文件 SQL Server 資料庫中。For SQL Server logging to function properly, you must have a stored procedure named report_event in the SQL Server database that can receive and parse the XML documents from NPS.

資格網域系統管理員」,或等最小,才能完成此程序。Membership in Domain Admins, or equivalent, is the minimum required to complete this procedure.

若要設定登入 NPS SQL ServerTo configure SQL Server logging in NPS

  1. NPS 主機或 NPS Microsoft Management Console (MMC) 嵌入式管理單元開放。Open the NPS console or the NPS Microsoft Management Console (MMC) snap-in.
  2. 主控台中,按一下 [計量In the console tree, click Accounting.
  3. 在詳細資料窗格中,在SQL Server 登入屬性,按一下 [變更 SQL Server 登入屬性In the details pane, in SQL Server Logging Properties, click Change SQL Server Logging Properties. SQL Server 登入屬性對話方塊。The SQL Server Logging Properties dialog box opens.
  4. 下列資訊的登入,選取您想要登入資訊:In Log the following information, select the information that you want to log:
    • 若要登入的所有計量要求,按一下 [計量要求To log all accounting requests, click Accounting requests.
    • 驗證要求登入,請按一下驗證要求To log authentication requests, click Authentication requests.
    • 若要登入定期計量狀態,按一下 [定期計量狀態To log periodic accounting status, click Periodic accounting status.
    • 若要登入定期狀態,例如暫時計量要求,按一下 [定期狀態To log periodic status, such as interim accounting requests, click Periodic status.
  5. 若要設定的之間執行 NPS 及 SQL Server 的伺服器允許同時工作階段,請輸入數字最大值數字同時工作階段的To configure the number of concurrent sessions allowed between the server running NPS and the SQL Server, type a number in Maximum number of concurrent sessions.
  6. 在 [設定 SQL Server 資料來源,SQL Server 登入,按一下 [設定To configure the SQL Server data source, in SQL Server Logging, click Configure. 資料連結屬性對話方塊。The Data Link Properties dialog box opens. 連接索引標籤上,指定動作:On the Connection tab, specify the following:
    • 若要指定儲存資料庫伺服器的名稱,請輸入,或選取名稱選取或輸入伺服器名稱To specify the name of the server on which the database is stored, type or select a name in Select or enter a server name.
    • 若要指定要用來登入伺服器的驗證方法,請按一下使用 NT 整合式的安全性To specify the authentication method with which to log on to the server, click Use Windows NT integrated security. 或按一下 [使用特定的使用者名稱和密碼,然後輸入認證中的的使用者名稱密碼Or, click Use a specific user name and password, and then type credentials in User name and Password.
    • 若要允許空白的密碼,請按一下空白密碼To allow a blank password, click Blank password.
    • 若要儲存的密碼,請按一下允許將密碼儲存To store the password, click Allow saving password.
    • 若要指定要資料庫連接到執行 SQL Server 的電腦上,按一下 [選取伺服器上的資料庫,然後從清單選取資料庫的名稱。To specify which database to connect to on the computer running SQL Server, click Select the database on the server, and then select a database name from the list.
  7. 若要測試 NPS 和 SQL Server 之間的連接,請按一下測試連接To test the connection between NPS and SQL Server, click Test Connection. 按一下[確定]以關閉 [資料連結屬性Click OK to close Data Link Properties.
  8. 登入失敗動作,請選取讓文字檔案登入容錯移轉的如果您想要 NPS 繼續文字檔案登入如果 SQL Server 登入失敗。In Logging failure action, select Enable text file logging for failover if you want NPS to continue with text file logging if SQL Server logging fails.
  9. 登入失敗動作如果登入失敗時,會捨棄連接要求如果您想要停止處理要求存取訊息時登入的檔案完全或無法使用某些原因 NPS。In Logging failure action, select If logging fails, discard connection requests if you want NPS to stop processing Access-Request messages when log files are full or unavailable for some reason. 如果您想繼續處理連接要求如果登入失敗 NPS,不會選取此核取方塊。If you want NPS to continue processing connection requests if logging fails, do not select this check box.

Ping 使用者名稱Ping user-name

某些 RADIUS proxy 伺服器和網路存取伺服器定期驗證 NPS 伺服器會顯示在網路上傳送驗證及計量要求(稱為 ping 要求)。Some RADIUS proxy servers and network access servers periodically send authentication and accounting requests (known as ping requests) to verify that the NPS server is present on the network. 這些 ping 要求包含虛構使用者名稱。These ping requests include fictional user names. NPS 處理這些要求時,存取退回記錄,讓它更難來保留有效記錄成為填滿事件及計量登。When NPS processes these requests, the event and accounting logs become filled with access reject records, making it more difficult to keep track of valid records.

當您設定登錄項目適用於ping 使用者名稱、NPS 其他伺服器符合 ping 要求的使用者名稱值對登錄項目值。When you configure a registry entry for ping user-name, NPS matches the registry entry value against the user name value in ping requests by other servers. A ping 使用者名稱登錄指定虛構使用者名稱(或使用者名稱模式,變數,以符合虛構使用者名稱)傳送 RADIUS proxy 伺服器或網路存取伺服器。A ping user-name registry entry specifies the fictional user name (or a user name pattern, with variables, that matches the fictional user name) sent by RADIUS proxy servers and network access servers. NPS 時收到 ping 要求符合ping 使用者名稱登錄項目值、NPS 拒絕驗證要求處理,此要求。When NPS receives ping requests that match the ping user-name registry entry value, NPS rejects the authentication requests without processing the request. NPS 記錄交易涉及虛構中的使用者名稱任何登入檔案,讓事件登入變得更容易上尚未取得共識。NPS does not record transactions involving the fictional user name in any log files, which makes the event log easier to interpret.

Ping 使用者名稱預設不會安裝。Ping user-name is not installed by default. 您必須將ping 使用者名稱登錄。You must add ping user-name to the registry. 您可以使用作業系統登錄新增項目。You can add an entry to the registry using Registry Editor.

警告

編輯登錄錯誤嚴重可能會損壞您的系統。Incorrectly editing the registry might severely damage your system. 變更登錄以前,您應該備份在電腦上的任何重要的資料。Before making changes to the registry, you should back up any valued data on the computer.

若要新增 ping 使用者名稱登錄To add ping user-name to the registry

Ping 使用者名稱新增下列機碼至字串值的系統管理員本機群組成員:Ping user-name can be added to the following registry key as a string value by a member of the local Administrators group:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IAS\Parameters

  • 名稱:Name: ping user-name
  • 輸入:Type: REG_SZ
  • 資料:的使用者名稱Data: User name

提示

若要指出多個使用者名稱為ping 使用者名稱值,輸入名稱模式,包括萬用字元,在 [DNS 名稱,例如資料To indicate more than one user name for a ping user-name value, enter a name pattern, such as a DNS name, including wildcard characters, in Data.